Last updated 30 July 2026
Data Processing Agreement (DPA)
For law firms using LexAgenda as a B2B service, a Data Processing Agreement may be required when LexAgenda processes personal data on your behalf. This page explains the relationship and how to obtain a draft — it is not itself a signed or binding DPA.
Who this is for
Customer organizations (law firms and cabinets) that process client or case personal data in LexAgenda. In that relationship, the customer firm is the controller and IT Union SRL (operator of LexAgenda) acts as processor for data you enter into the product.
Roles (overview)
Controller — your law firm: decides why and how client/case data is processed in LexAgenda. Processor — IT Union SRL: processes that data only to provide the service, under your documented instructions and applicable law (including GDPR Art. 28). Account, authentication, and billing data about your users may be processed by IT Union SRL as an independent controller — see the Privacy Policy and GDPR overview.
Processing scope (summary)
Subject matter: personal data in client/case records, hearings, documents, and related firm content you store in LexAgenda. Nature: hosting, storage, transmission, display, backup, and support as needed to operate the SaaS. Purpose: provide LexAgenda features you enable. Duration: for the term of your organization’s use of the service, plus limited retention needed for backups, security, and legal obligations. Full schedules (categories of data subjects, technical/organizational measures, international transfers) belong in the signed DPA document.
Subprocessors
To run the service, LexAgenda engages subprocessors in these categories (as configured): • application hosting and infrastructure (including database hosting); • object/file storage for case files; • transactional email delivery; • payment processing when enabled (primarily billing data; may appear in processor schedules where relevant); • bot/abuse protection (CAPTCHA) on authentication when configured; • product analytics when configured; • error/performance monitoring when configured; • optional in-app support chat when enabled. A current list of subprocessors is available on request to B2B DPA customers at legal@lexagenda.ro. We will notify customers of material subprocessor changes as provided in the signed DPA. Portal JUST is an official public data source used for sync features; it is not engaged by LexAgenda as a subprocessor for your client files.
How to obtain a DPA
We do not publish a fake signed agreement on this site. When you need a DPA for procurement or compliance: 1. Email legal@lexagenda.ro with your firm name and contact. 2. We will share a draft DPA (including schedules) for review with your counsel. 3. The agreement becomes binding only once both parties sign (or otherwise formally accept) it. At signup, organizations may acknowledge DPA intent in-product; that acknowledgment does not replace a negotiated signed DPA if your counsel requires one.
Contact
IT Union SRL CUI: RO35358991 Str. 1 Decembrie 1918, nr. 24 Craiova, Romania legal@lexagenda.ro
Disclaimer
This page is informational. It is not legal advice and not a binding processing contract. Have your counsel review any DPA before signing.
Related